Cybersecurity Roles and Responsibilities
Purpose
This document defines the main cybersecurity responsibilities within the company.
One person may perform several roles in a smaller company. The important point is that each responsibility has a clear owner.
Leadership
Leadership is responsible for:
- Approving cybersecurity priorities
- Providing appropriate resources
- Reviewing significant cyber risks
- Approving major risk acceptance decisions
- Supporting incident response decisions
- Ensuring cybersecurity is treated as a business responsibility
Primary owner: ____________________
Backup: ____________________
Cybersecurity Coordinator
The cybersecurity coordinator is responsible for:
- Coordinating the cybersecurity playbook
- Maintaining the Master Action Tracker
- Coordinating risk reviews
- Following up on security actions
- Coordinating incident preparedness
- Maintaining key security contacts
- Preparing leadership updates
Primary owner: ____________________
Backup: ____________________
IT / Technical Owner
The IT or technical owner is responsible for:
- Device and system security
- Patch management
- Endpoint protection
- Secure configuration
- Account administration
- MFA implementation
- Logging and monitoring
- Backup operations
- Technical incident containment and recovery
Primary owner: ____________________
Backup / MSP: ____________________
Data and System Owners
Business owners of important systems and data are responsible for:
- Confirming who requires access
- Approving access where appropriate
- Reviewing access periodically
- Identifying business criticality
- Supporting recovery priorities
- Confirming restored systems work correctly
System / data owners should be recorded in the relevant inventory.
HR
HR is responsible for supporting:
- Employee onboarding
- Employee offboarding
- Role changes
- Security training coordination
- Employee-related incident handling
- Insider threat escalation where appropriate
HR owner: ____________________
Finance
Finance is responsible for:
- Payment verification controls
- Bank-detail change verification
- Financial system access approval
- Fraud escalation
- Supporting investigation of payment-related incidents
Finance owner: ____________________
Managers
Managers are responsible for:
- Approving appropriate employee access
- Reporting role changes promptly
- Supporting secure onboarding and offboarding
- Escalating suspicious activity
- Preventing unsafe workarounds
- Reinforcing cybersecurity expectations with their teams
Employees and Contractors
All users are responsible for:
- Protecting credentials
- Using MFA correctly
- Using approved systems and tools
- Handling data appropriately
- Keeping devices secure
- Following security procedures
- Reporting suspicious activity promptly
- Reporting security mistakes immediately
Vendor / MSP Owner
A named internal person should own important third-party relationships.
Responsibilities include:
- Approving vendor access
- Knowing what systems the vendor can access
- Maintaining vendor contacts
- Reviewing vendor access
- Confirming access is removed when no longer required
- Escalating vendor-related security issues
Owner: ____________________
Incident Response Lead
The incident response lead is responsible for:
- Activating the incident response process
- Coordinating triage
- Maintaining the incident record
- Coordinating containment
- Escalating to leadership
- Managing external technical support
- Ensuring decisions are documented
- Handing the incident into recovery and review
Primary incident lead: ____________________
Backup incident lead: ____________________
Recovery Lead
The recovery lead is responsible for:
- Coordinating restoration
- Following recovery priorities
- Confirming trusted restore sources
- Coordinating technical and business validation
- Tracking recovery status
- Handing completed recovery into post-incident review
Primary recovery lead: ____________________
Backup: ____________________
Security Awareness Owner
The security awareness owner is responsible for:
- Planning employee training
- Tracking completion
- Coordinating role-based training
- Running or arranging simulations and exercises
- Updating training after incidents and near misses
Owner: ____________________
Review Frequency
Cybersecurity ownership should be reviewed:
- At least annually
- When key personnel change
- When the MSP or major vendors change
- After significant incidents
- When important business systems or responsibilities change
Practical Rule
Every important cybersecurity responsibility should have one clearly accountable person and a backup wherever practical.